-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Bug]: hull.js Code Injection Vulnerability #6605
Comments
Would you be willing to contribute to update the version of this dependency? |
@Aarebecca 既然我们不想引入 github link 的库,是否有其他的替代库能避免这个库注入漏洞的问题? |
@Rey-Wang 也许可以考虑将该库的源码拷贝至 G6 内部 |
Hello, this library was created more than 10 years ago. It is deprecated and not maintained, I would not recommend using it. I’d suggest to search for alternatives. |
Hello! Could we re-open this issue? |
Should be just: gather alternatives, check them for robustness, compatibility, and performance, then replace hull.js with the best alternative |
You can conduct research on the libraries that are closest in capabilities to hull.js. You can consider several factors:
|
Any news on defining the hull.js replacement? |
A typed copy of hull.js is better. However, since the author don't recommend using it any more + potential security risks, an existing alternative can be an instant upgrade than hull.js, and would be much easier for future maintainace. (Unless you are going to fix & improve hull.js to your own liking)
|
@zhongyunWan may I ask when we will release the fix? |
Describe the bug / 问题描述
could we upgrade to the latest version? also, new version of hull.js is not hosted on npm
Reproduction link / 复现链接
No response
Steps to Reproduce the Bug or Issue / 重现步骤
No response
G6 Version / G6 版本
🆕 5.x
OS / 操作系统
Browser / 浏览器
The text was updated successfully, but these errors were encountered: